VG Stuttgart - 11 K 3946/21
| VG Stuttgart - 11 K 3946/21 | |
|---|---|
| Court: | VG Stuttgart (Germany) |
| Jurisdiction: | Germany |
| Relevant Law: | Article 4(1) GDPR Article 5(1)(a) GDPR Article 12(3) GDPR Article 12(5) GDPR Article 15(1) GDPR Article 15(3) GDPR Article 23 GDPR Article 79(1) GDPR § 34(1)(2)(a) BDSG § 44(1) BDSG |
| Decided: | 30.11.2023 |
| Published: | 30.11.2023 |
| Parties: | Postbeamtenkrankenkasse (PBeaKK, German Postal Civil Servants’ Health Insurance Fund) Employee of Deutsche Bundespost (nowadays Deutsche Telekom) |
| National Case Number/Name: | 11 K 3946/21 |
| European Case Law Identifier: | ECLI:DE:VGSTUTT:2023:1130.11K3946.21.00 |
| Appeal from: | |
| Appeal to: | Appealed - Confirmed [[:Category:VGH Baden-Württemberg [Germany]|VGH Baden-Württemberg [Germany]]] 2 S 560/24 |
| Original Language(s): | German |
| Original Source: | Landesgericht Baden-Württemberg (in German) |
| Initial Contributor: | avalang |
A court held that the right to information under Article 15 GDPR includes documents related to health benefits that contain personal data, including correspondence, and that the controller needs to be able to respond to large data requests.
English Summary
Facts
The data subject was a civil servant for one of the companies (Bundesanstalt für Post und Telekommunikation (BAPT)) the controller manages the employee's health insurance benefits of.
On 13 June 2018, the data subject sent a telefax to the controller, looking to exercise their Article 15 GDPR right to obtain from the controller a confirmation as to whether or not personal data concerning them are being processed, and, where that is the case, access to the personal data in a detailed list.
The controller responded on 2 July 2018, covering all aspects of Article 15 GDPR (a)-(h) in a one page document containing name, address, birth date, employee ID, tax ID, bank information, type of insurance, beginning of insurance as well as which group and pay scale. It also contained a general listing of billing documents and digitized receipts and outgoing mail since 2007.
The data subject was not satisfied with this response, criticizing the lack of health data, missing information about the health reimbursement record for civil servants (Beihilfeakte), and an incorrect phone number.
The controller replied to the complaint on 1 August 2018, saying that the phone number was deleted and offering examples of health data in the form of past doctors the data subject frequented.
The data subject was yet again not satisfied and filed a disciplinary complaint at a data protection authority as the disclosure was deemed incomplete.
The controller referred to Article 23 GDPR in conjunction with § 34(1)(2)(a) German Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG), stating they store approximately 3,000 documents, some with multiple pages, relating to the client due to the retention period of 10 years. It also claimed that the employer of the data subject has expressly reserved the right to respond to data requests based on Article 15 GDPR for themselves.
The data subject kept repeatedly reaching out to the controller about its incomplete data inquiry, on 27 August 2018, 02 April 2020, 16 May 2020 respectively.
The controller responded on 1 September 2020 with an electronic overview in form of a CD of all saved personal data pertaining to the data subject from 01 January 2014 to date.
The data subject reached out yet again via telefax on 03 September 2020, and had to resubmit this on 21 January 2021 as the original was deemed lost. In it, they once again criticize the incomplete results of the inquiry.
The controller denied the request for information by the data subject on 01 June 2021 based on Article 23 GDPR in conjunction with § 34(1)(2)(a) BDSG as they see the request as fulfilled per the documents delivered on 02 July 2018 and 01 September 2020 respectively and insisted that there is no right to acquire the complete contents of entire folders, and that the data subject must be aware of the data as it primarily contains documents the subject themselves submitted. It alleged that fulfilling the request would involve a disproportionate amount of work, and any need for information by the data subject was to be regarded as minimal at best.
The data subject objected to the controller's decision. They criticized that the decision was not made in a timely manner, crossing the deadline of one month stated by Article 12(3) GDPR, that the documents provided were incomplete and that the decision document itself was flawed.
On 08 July 2021, the controller denied the data subject's objection. It insisted that the denial was substantively legal and that much of the data the data subject is seeking is not held or processed by them.
Finally, the data subject filed a lawsuit with the administrative court on 3 August 2021 (Article 79(1) GDPR in conjunction with Article 15 GDPR) in an attempt to get a complete information from the controller, referencing the court decision of the German Federal Court of Justice (Bundesgerichtshof - BGH) VI ZR 576/19 on what constitutes a complete and substantive confirmation under Article 15 GDPR. They criticize that there must be more internal e-mail communication about him at the controller, as well as more data in general, not just starting at 2014.
The controller alleged that the data subject's requests were unspecific, excessive and abusive.
Holding
The court considered that the request by the data subject was reasonably specific, not excessive or abusive. It also considered the reaction of the controller to be timely, but ruled that there was no general right for the controller to refuse to provide the data subject with the requested information, based on the lack of excess or abuse.
It did not see the supplying of 3,000 documents as excessive, either, and held that it is the responsibility of the controller to implement an IT infrastructure that would allow this type of request to be fulfilled. It also did not matter according to the the court that the data subject could possibly use the results of the requests for matters unrelated to data protection.
The court held that the appropriate type of action for asserting a claim to information via the GDPR directed against a public authority under Article 15 GDPR is an action for an order to act (Verpflichtungsklage) and references the Federal Administrative Court (BVerwG) judgment of 16 September 2020 – 6 C 10.19.
Finally, the court opined that the right to information under Article 15 GDPR covers documents related to benefit transactions like submitted invoices, diagnoses, x-ray images, expert reports, and more that are stored by the health benefits office for former postal civil servants or by the health insurance itself. The controller shall have the choice between either taking the personal data out of the document and supplying it separately, or offering entire copies that are censored as needed, of the 3,000 documents. It excluded any deleted data as well as data relating to unauthorized employee acts beyond authority (Mitarbeiterexzess), like emails between employees about the data subject.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the German original. Please refer to the German original for more details.
Operative part
The defendant is required, pursuant to Article 15 (1), second half of the GDPR, to provide the plaintiff with information about the personal data concerning him that it processes, taking into account the court's legal opinion regarding the scope, form, and time frame.
To the extent that the defendant's decision of June 1, 2021, and its objection decision of July 8, 2021, conflict with this, they are set aside.
The rest of the action is dismissed.
The plaintiff shall bear two-thirds of the costs of the proceedings and the defendant one-third.
The appeal is allowed.
Facts
Paragraph 1
The plaintiff is challenging the defendant's handling of a request for information pursuant to Article 15 GDPR by means of a so-called direct action pursuant to Article 79(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; hereinafter GDPR) and is requesting further information about his personal data held there.
Paragraph 2
The defendant is a public corporation. On behalf of the federal government, it handles the subsidy matters of civil servants of the former postal companies and, as an insurer, also provides benefits not covered by the subsidy to its insured members based on its statutes. It also acts as an interface to the "Community of Private Insurance Undertakings for the Implementation of Long-Term Care Insurance pursuant to the Nursing Care Act of May 26, 1994, for Members of the Postal Officials' Health Insurance Fund and the Health Insurance Fund for Federal Railway Officials (GPV)." It collects insurance premiums and, where applicable, provides benefits, which it then settles internally with the GPV.
Paragraph 3
The plaintiff, born in 19XX, is a civil servant of the former Deutsche Bundespost, now Deutsche Telekom, and a member of the defendant's member group B 1. His wife, born in 19XX, was also co-insured – at least temporarily. According to the plaintiff's statements at the oral hearing, his daughter is also co-insured.
Paragraph 4
The defendant has offered its members the opportunity to communicate with it in writing – including by fax – and electronically – including by email – and via its own so-called submission app. Within the framework of the procedure it calls "direct billing," the defendant has also opened up the possibility for service providers to directly bill the defendant for services provided to members of the defendant.
Paragraph 5
A few days after the General Data Protection Regulation came into force on May 25, 2018, the plaintiff contacted the defendant for the first time by fax on June 13, 2018. Referring to Article 15 GDPR, he requested information as to whether personal data concerning him was being processed and, if so, requested a detailed list/information, quoting the wording of Article 15 (1), second half of the sentence, letters a) to h) GDPR. He also pointed out that the information had to be provided in full.
Paragraph 6
The defendant responded to the plaintiff on July 2, 2018. The defendant explained the basic principles of its data collection and processing in general terms and provided information on all points of Article 15 (1), second half of the sentence, GDPR (a) to (h). In addition, the defendant enclosed a one-page document listing information about the plaintiff (including name, address, date of birth, personnel number, tax ID, bank details), the insurance relationship (including start date, group membership, tariff classes), and the claims settlement to date in general terms (including "billing documents: digitized receipts and outgoing mail since 2007").
Paragraph 7
The plaintiff was dissatisfied with this and complained by fax dated July 3, 2018, about the missing health-related data, information on the benefits file, and an incorrect telephone number in the personnel data.
Paragraph 8
In a letter dated August 1, 2018, the defendant initially informed the plaintiff that the telephone number had been deleted. Health data was recorded via the documents submitted by the plaintiff, which were archived. He was informed, for example, of treating physicians and service providers from previous months. Communication data (email address, fax number) was also stored via corresponding incoming documents, which were archived.
Paragraph 9
By fax dated August 3, 2018, the plaintiff filed a "service/professional supervisory complaint." The information was incomplete.
Paragraph 10
The administrative file submitted by the defendant to the court contains no incoming documents for the following (almost) two years. An administrative file from the Federal Commissioner for Data Protection, which was consulted, shows that the plaintiff corresponded with the supervisory authority from August 4, 2018, in which he complained about the defendant's lack of willingness to provide information. The supervisory authority contacted the defendant and the plaintiff on several occasions. In this context, the defendant (also) relied on Article 23 GDPR in conjunction with Section 34 (1) No. 2 (a) of the Federal Data Protection Act (BDSG). Approximately 3,000 documents – some of them multi-page – relating to the plaintiff were archived due to the retention periods of 10 years. Furthermore, the defendant explained to the supervisory authority that the Federal Office for Posts and Telecommunications (BAPT), on whose behalf it handles federal civil servants' benefits matters, had expressly reserved the right to respond to inquiries regarding benefits pursuant to Article 15 GDPR.
Paragraph 11
In addition, the plaintiff contacted the Federal Minister of Finance on October 27, 2018. He also initiated proceedings for information under the Freedom of Information Act.
Paragraph 12
In an ongoing state aid proceeding, the plaintiff also contacted the defendant's management board on August 27, 2018. In addition to statements regarding the state aid procedure, this letter also contains a "specific query pursuant to Art. 15 GDPR regarding all ... stored external data ... as well as an electronic copy of the data." This letter did not reach the defendant's office in the administrative file submitted in the court proceedings. However, it can be found in the administrative file of the Federal Commissioner for Data Protection that was consulted.
Paragraph 13
The same applies to a letter from the plaintiff dated April 2, 2020, again addressed to the defendant's management board and administrative board. The statements there also concern - initially - an ongoing state aid proceeding. In addition, the plaintiff then reminds the defendant of his request for information pursuant to Art. 15 GDPR, which is still pending.
Paragraph 14
A further letter from the plaintiff dated May 16, 2020, again initially addressed to the defendant's management/administrative board, was then filed by the defendant as a so-called "duplicate file" in addition to the aid file, now also in the procedural file relating to the right to information pursuant to Art. 15 GDPR. The plaintiff initially refers to his still outstanding right to information. At the same time, he requests that the data disclosure be "updated to the present day" because the data set has changed.
Paragraph 15
On September 1, 2020, the defendant wrote to the plaintiff and referred to an attached overview "in electronic form" of the personal data stored about him, as well as copies of the documents submitted by the plaintiff and archived by the defendant "from January 1, 2014 to the present, relating to insurance benefits." The copy of this letter contained in the administrative files does not reveal what the defendant enclosed with the plaintiff. However, in its subsequent correspondence with the supervisory authority, the defendant stated that a CD containing data had been sent to the plaintiff at the time.
Paragraph 16
According to the plaintiff, he then sent another letter by fax to the defendant on September 3, 2020. This letter is not contained in the defendant's administrative files. However, there must have been communication between the parties regarding the possible loss of this letter. In a letter to the defendant dated January 21, 2021, the plaintiff refers to this and states that he enclosed the "allegedly non-existent letter dated September 3, 2020." Although no attachment to this letter dated January 21, 2021, can be found in the defendant's administrative files, the defendant did not, in subsequent correspondence, complain that nothing had actually been enclosed. In any case, the plaintiff submitted his letter of September 3, 2020, to the defendant in the court proceedings. The letter criticized the incompleteness of the information. It contained neither "statements, correspondence with the Federal Office for Public Prosecutions (BAPT), emails, etc." The aid file was also missing. Processing, notes, statements, and internal and external correspondence were not disclosed.
Paragraph 17
The defendant had already supplemented its information to the plaintiff in a letter dated December 22, 2020. It referred to a notice from the Federal Commissioner for Data Protection, according to which correspondence with her regarding the information procedure was also subject to disclosure. According to the copy of the letter of December 22, 2020, contained in the administrative files, this correspondence was therefore enclosed. A file note stating what was enclosed and in what form is not included. In this respect, however, the plaintiff did not subsequently complain that he had not received anything attached to the letter dated December 22, 2020.
Paragraph 18
In any case, in a letter dated January 12, 2021, the plaintiff again complained that the information provided so far was insufficient. Finally, in the aforementioned letter dated January 21, 2021, in which he stated that he sent the "allegedly nonexistent letter dated September 3, 2020" to the defendant, he summarized that information on data was still missing. He cited "data from the last 10 years (the storage period)," "documents relating to the aid," "statements, correspondence with the BAPT," "emails," "submission of my letters and co-signatures," "hearing of the Executive Board (letter, memo)," "processing and forwarding notes, knowledge of the response, etc." regarding complaints he had submitted from the board's complaint log. He could not determine the shortage himself. He needed the entire process to be clearly understood.
Paragraph 19
Finally, by decision of June 1, 2021, the defendant rejected the plaintiff's "request of January 21, 2021 for the transmission of further data and documents." The reason given was that the right to information under Art. 15 GDPR was met in this case by the letters of July 2, 2018, and September 1, 2020. There was no right to the disclosure of the entire contents (e.g., files). Entire files were not personal data. Therefore, the complete administrative documents from the last ten years could not be transmitted. There was also no right to the disclosure of applications and declarations because these documents alone contained the master data as personal data, and information had already been provided on this master data. The plaintiff was already aware of the content of the administrative documents because they were either applications and supporting documents that he had submitted himself or notices and letters from the defendant that had been sent to him. This also applies to the content of the letters of complaint addressed to the defendants. Therefore, there is no protective purpose in making these documents available to him again.
Paragraph 20
Separate documents relating to the subsidy are not available due to the so-called "joined procedure" practiced by the defendant. For this reason alone, a corresponding claim to the provision of documents is ineffective. The subsidy is processed by the Postal Officials' Health Insurance Fund in accordance with Section 16 (2) and Section 26d (3) of the Federal Postal Services Act (BAPostG). Within the framework of the so-called joined procedure, the health insurance benefits and the subsidy are determined in one notice, which is why the receipts for the expenses (e.g., doctor's bills, prescriptions) simply need to be submitted. This means that no separate documents relating to the subsidy exist. A corresponding request for information under Article 15 of the GDPR is therefore ineffective.
Paragraph 21
To the extent that the plaintiff requests the submission of emails, it is already not sufficiently clear which emails are to be affected. Regarding emails in the administrative documents, reference is made to the above statements.
Paragraph 22
The same applies to the submission of letters addressed to the plaintiff, which are part of the administrative file. Letters to insured persons are also not "co-signed," as the corresponding processes are regularly digitized.
Paragraph 23
To the extent that the plaintiff requests information about data/documents for the hearing of the Executive Board, it is already not sufficiently clear which facts are to be affected. The defendant maintains an incoming mail register in the Executive Board office, in which the date of receipt of letters addressed to the Executive Board, the sender, and the internal department to which the letter in question was forwarded are recorded. This incoming mail register is maintained in the data format of an Excel spreadsheet. This incoming mail log also contains, but is not limited to, letters of complaint. If the plaintiff has sent letters to the board in the past, his first and last name and the date of receipt are likely to be included in this incoming mail log.
Paragraph 24
Regardless of the above, there is clearly no legal interest in submitting stored documents from the past ten years. This is because compiling and printing the relevant documents would involve a disproportionate amount of work, and the need for information – if any – can be considered minimal at best.
Paragraph 25
Furthermore, the defendant, as a public corporation, decides on requests for information pursuant to Art. 15 GDPR by administrative act (decision) within the meaning of Section 35 of the Administrative Procedure Act (VwVfG).
Paragraph 26
The plaintiff filed an objection to this decision within the deadline. He argues that the decision is formally flawed. Firstly, it was "out of time" because the one-month deadline for providing information was not met, and "the signature" was also not lawful. The decision originated from the very body against which the complaint was filed. It also interfered with the ongoing appeals process, which was inappropriate, as clarification from a neutral party - "the specialist party at the Federal Institute for Data Protection and Freedom of Information" - was clearly not desired. The plaintiff was expressly granted the right to appeal.
Paragraph 27
The decision was also incorrect in substance. It contradicted the requirements of the responsible supervisory authority (Federal Commissioner for Data Protection and Freedom of Information, the Federal Institute for Data Protection and Freedom of Information), which the latter had explained to the defendant on several occasions. He had so far received only incomplete information. Furthermore, an appeals process regarding the retention period for the state aid data was underway, so it would have been necessary and expedient to await the results. Furthermore, it is completely incomprehensible why the defendant is now adopting a completely different legal opinion, given that it has already agreed with the legal opinion of the competent supervisory authority and requested the defendant to provide the missing data in order to provide it, which it now refuses to do in the decision. What he has received so far is a copied, incomplete package from an IT system, but no other data that is undoubtedly present and personal.
Paragraph 28
There is also no "excessive" behavior, as he has not yet received any (sufficient) information. The administrative files contain not only master data, but also subsidy and health data, as well as treatments performed, etc.
Paragraph 29
He himself does not conduct any email correspondence with the defendant. His request for information regarding the requested emails logically refers to the email correspondence conducted about him, both internally and externally.
Paragraph 30
Even if the administrative files only contain data submitted by him, he has the right under the GDPR to review the processing by submitting a copy, which also applies to older cases.
Paragraph 31
The same applies to the "complaints book." His data (date of receipt, reason for the complaint, processing by, etc.) must be disclosed.
Paragraph 32
The decision is unclear on the question of "co-signature." If the defendant processes cases "digitally," these electronically created drawings, templates, etc. must be submitted. Based on the limited data available, he can determine that this is probably done by email. These must therefore be submitted.
Paragraph 33
The information on the aid procedure is not comprehensible. There is certainly data that only concerns the aid. On the one hand, he must be able to check whether aid data is being deleted lawfully in accordance with the Federal Aid Ordinance. Since this data is also being denied to him, he cannot verify the lawful data processing.
Paragraph 34
He also stated that benefits and health insurance benefits that were billed directly (e.g., hospital benefits) were not disclosed to members, or not disclosed in full.
Paragraph 35
He also stated that the legal proceedings between him and the defendant were not disclosed, although further data (letters with the courts, internal correspondence, initiated reimbursements, etc.) should be available.
Paragraph 36
He stated that the benefits data taken over by the Federal Association of Public Health (BAPT) were neither disclosed nor mentioned. The same applies to data on long-term care insurance. The defendant calculates the contributions and exchanges data with third parties in this regard.
Paragraph 37
Even within the framework of regular contribution increases, there must be personal data that he must be able to verify, such as the amount of his provisions and other personal data used in the calculation. He must be able to verify this. Especially in light of the contribution increase of approximately 42% received on July 1, 2021, the calculation and the data basis appear at least dubious.
Paragraph 38
It is also unclear why data on marital status were refused, even though they were personal.
Paragraph 39
To the extent that the information was refused due to increased effort, this violates higher court case law.
Paragraph 40
The information provided is also insufficient in this respect, as, for example, the third parties to whom his data is shared and from whom the defendant receives data are not even mentioned. This is likely to include, among others, the provider of the "submission app."
Paragraph 41
In addition, the plaintiff's letter of objection contains further allegations regarding the defendant's administrative actions and requests to inform numerous internal departments and external supervisory authorities about the process.
Paragraph 42
By decision of July 8, 2021, the defendant rejected the plaintiff's objection. The contested decision is formally lawful. No person who would be excluded under Section 20 of the Administrative Procedure Act (VwVfG) or who is suspected of bias participated in the issuance of the decision. Furthermore, there are no statutory deadlines for issuing a rejection decision. Finally, the decision contains the name and signature of the authorized representative (Section 37 (3) VwVfG); thus, there is a lawful "signature."
Paragraph 43
The decision of June 1, 2021, is also substantively lawful, as the transmission of the specified additional documents and data was rightly refused. A claim to the transmission of entire files cannot be derived from Article 15 (3) GDPR. The PBeaKK does not maintain a separate subsidy file on the plaintiff, so that, for factual reasons alone, no documents and data from this file can be made available. To avoid repetition, please refer to the detailed reasoning in the initial decision of 1 June 2021 for details.
Paragraph 44
The plaintiff filed a lawsuit with the Administrative Court on August 3, 2021. He claims he is seeking "lawful" and "complete" information. What constitutes lawful and complete information is determined by the case law of the Federal Court of Justice (VI ZR 576/19) and a letter from the Federal Commissioner for Data Protection dated August 12, 2020, during a hearing with the defendant, which the plaintiff submitted. He specified his right to information in the letter "dated September 3, 2021" (meaning September 3, 2020) and in the letter of objection. Ultimately, he received two encrypted CDs each containing data from the accounting system and correspondence between the defendant and the Federal Commissioner for Data Protection. Since he always addressed his letters to the defendant to the Executive Board, there must have been internal forwarding letters and notes. This, too, was not disclosed to him. The data transmitted to him from the accounting system only covered the period from 2014 to week 36 of 2020. However, given the 10-year storage period, older data must also exist. Furthermore, he also has rights to information under civil service law and the Freedom of Information Act. In any case, the ECJ has now accepted a broad right to information under the General Data Protection Regulation.
Paragraph 45
Contrary to the statements in the contested decision, this is not a request for information dated January 21, 2021, but rather a request for the missing data from the 2018 request. Whether he already has this data is irrelevant, as he must be able to obtain information about the data processing.
Paragraph 46
The defendant has opposed the plaintiff's request. The lawsuit still lacks a precise and specific definition of what information is still required. Procedurally, there is also a lack of a specific claim that would allow the court to enforce its decision. Furthermore, the case law of the ECJ indicates that the right to information and the right to receive copies of the data are intended to effectively exercise the rights conferred by the General Data Protection Regulation, namely the right to rectification, erasure, or restriction of processing. All applications submitted by the plaintiff, the supporting documents submitted, and the decisions issued are stored as actually submitted, presented, or issued. They therefore cannot be "false" in the sense of data processing. The plaintiff's request thus also constitutes abusive and excessive in nature. All of the plaintiff's speculations about allegedly additional data are mere "out of the blue" claims.
Paragraph 47
The plaintiff responded by arguing that, due to conflicting statements regarding retention periods, he also had a right to information about which billing data – of which he was aware – was still stored by the defendant. He first submitted a request for information in 2018, which he argued was neither excessive nor abusive. In the decision of June 15, 2021, to which he referred, the Federal Court of Justice expressly stated that internal notes or internal communications within the party obliged to provide information, which contained information about the person requesting information, could, in principle, be considered as the subject of the right to information under Article 15 (1) GDPR.
Paragraph 48
During the oral hearing, the rapporteur extensively discussed the factual and legal situation with the parties. During the discussion, the plaintiff stated, among other things, that the Federal Commissioner for Data Protection had considered his appeal proceedings "settled" after the defendant had communicated the outcome of the administrative proceedings at hand. In this regard, a lawsuit is pending before the Cologne Administrative Court. The rapporteur granted the defendant the right to submit a final statement on the plaintiff's last written submission of September 13, 2023, within three weeks of the conclusion of the oral hearing, and the plaintiff the right to respond to it once. The issuance of a judgment will be postponed until then.
Paragraph 49
The defendant has exercised this right to submit a written statement. It argues that it has no data on the plaintiff regarding the private compulsory long-term care insurance, with the exception of the current contribution amount of €XX.XX, which it pays to the insurance companies. The plaintiff, as a user of the so-called submission app, was informed upon its launch that it was operated by IBM Deutschland GmbH, to whom the submitted personal data would thus be available. No direct billing has yet taken place with regard to the plaintiff. The dental chart filed for the plaintiff was attached to this pleading, which was submitted electronically to the court. The printout created for the court file – kept in paper form – produced a result that was difficult to decipher. Also attached was an overview of the diagnoses made to the plaintiff by the treating physicians. According to the date lines, these cover the period from the beginning of 2017 to January 2023. Presumably due to the change in format during the printout, the approximately 210 columns of dates cannot be properly assigned to the disproportionately higher number of columns with diagnoses (some with, some without ICD codes). Also attached was a table with seven stored advance approvals or authorizations for treatments in the period from October 2017 to August 2023, as well as a table with insurance data, excluding personal data.
Paragraph 50
The plaintiff has exercised his one-time right of reply. He points out that the submission of further personal data now confirms that the previous information was incomplete. However, health data is still missing. The same applies to long-term care insurance data. More data must be available than just the contribution amount. The same applies to the submission app. This is also used for communication. Presumably, his device, which is connected to the app, is also stored.
Paragraph 51
Direct billing had indeed occurred in the past. However, the defendant generally stated in its member magazine that data from direct billing could not be submitted. This violates the GDPR.
Paragraph 52
The submitted dental chart was illegible. However, there must also be stored service and treatment data, which the defendant uses to reject applications in the event of repeated applications (visual aids). Data on administrative and legal proceedings between the parties involved is still missing. The same applies to financial data.
Paragraph 53
The plaintiff requests (finally),
Paragraph 54
that the defendant's decision of June 1, 2021, in the form of the defendant's objection decision of July 8, 2021, be set aside and
Paragraph 55
that the defendant be ordered,
Paragraph 56
to fully comply with its right to information pursuant to Article 15 of the General Data Protection Regulation, taking into account the court's legal opinion, for a period 10 years back from the date the judgment became final.
Paragraph 57
The defendant requests,
Paragraph 58
that the action be dismissed.
Paragraph 59
For further details, reference is made to the pleadings submitted, the court files, and the defendant's administrative files consulted, as well as the administrative files of the Federal Commissioner for Data Protection consulted in the appeal proceedings conducted there.
Reasons for the Decision
Paragraph 60
1. The action is admissible.
Paragraph 61
a) According to Article 79(1) GDPR, which entered into force on May 25, 2016, and as a regulation within the meaning of Article 288(2) TFEU since May 25, 2018, binding in its entirety and directly applicable in all Member States even without implementing measures (ECJ, judgment of June 15, 2021 - C-645/19 -, juris, paras. 99 and 109 et seq.), every data subject has the right to an effective judicial remedy against, inter alia, a controller, without prejudice to any other administrative or non-judicial remedy, if they consider that the rights granted to them by the General Data Protection Regulation have been infringed by the processing of their personal data by the controller in breach of the Regulation.
Paragraph 62
Article 79(1) GDPR explicitly refers to a violation of law only in the case of “processing of data inconsistent with the Regulation.” This also includes the judicial enforcement of a right to information under Article 15 of the GDPR (LSG NRW, judgment of March 24, 2021 – L 12 AS 2102/19 –, juris, paras. 54 et seq.). Data subjects can also assert rights to information on the basis of Article 79 (1) GDPR (Bergt in Kühling/Buchner, GDPR, 3rd edition 2020, Article 79, para. 1; Kreße in Sydow, Eur. GDPR, 2nd edition 2018, Article 79, para. 7; expressly for a broad interpretation, see also: Martini in Paal/Pauly, GDPR, 3rd edition 2021, Article 79, paras. 22 et seq.).
Paragraph 63
b) The right to bring an action under Article 79 GDPR exists – as paragraph 1 of the provision shows – without prejudice to the possibility under Article 77 GDPR to lodge a complaint with a supervisory authority and – in the event of an unsatisfactory outcome of this complaint procedure – to subsequently bring an action against the supervisory authority under Article 78 (1) or (2) GDPR. The so-called "direct action" under Article 79 (1) GDPR directly against the controller is therefore completely independent of the complaint procedure. The plaintiff's allegation that the defendant "interfered" in the ongoing complaint procedure with its contested decision of June 1, 2021, is already irrelevant. Both procedures are independent of each other ("without prejudice").
Paragraph 64
c) The legal dispute between the parties is limited to the provisions of the General Data Protection Regulation. While Section 17, Paragraph 2, Sentence 1 of the German Civil Service Constitutional Court Act (GVG) stipulates that a competent court within the permissible legal process shall decide the legal dispute taking into account all relevant legal aspects, this presupposes, however, that the claims are identical, which may be based on different legal grounds, but otherwise aim for an identical result. Accordingly, a review of the plaintiff's right to information under the Freedom of Information Act is already ruled out here, because such a claim would trigger a fee, whereas the plaintiff is asserting a right to information free of charge. Claims under civil service law principles—inspection of the subsidy file in an ongoing subsidy procedure, or similar—cannot be the subject of the dispute because the plaintiff explicitly seeks fulfillment of a right to information by the defendant, not access to information of any kind.
Paragraph 65
d) The fact that Article 79 (1) GDPR does not specify any (restrictive) requirements for exercising the right to an effective judicial remedy does not mean that national law may not, in principle, establish such requirements (e.g., regarding legal recourse, standing, time limit for bringing an action, and the need for legal protection) (see this and the following on the comparable provision of Article 78 (1) GDPR, VG Hamburg, judgment of June 1, 2021 – 17 K 2977/19 –, juris paras. 40 et seq.). Article 79 (1) GDPR merely stipulates that an effective remedy must be available, but does not regulate its procedural modalities.
Paragraph 66
According to settled case-law of the Court of Justice of the European Union, in the absence of relevant provisions of EU law, it is for the domestic legal system of each Member State, in accordance with the principle of procedural autonomy, to lay down the detailed procedural rules applicable to actions for safeguarding the rights which individuals derive from EU law. However, those requirements must not be less favourable than those governing similar situations governed by domestic law (principle of equivalence) and must not make practically impossible or excessively difficult the exercise of rights conferred by EU law (principle of effectiveness) (ECJ 6 October 2020 - C-511/18 and others - [La Quadrature du Net and others], para. 223; 19 December 2019 - C-752/18 - [Deutsche Umwelthilfe], para. 33; 24 October 2018 - C-234/17 - [XC et al.] paras. 21 et seq. with further references; 6 October 2015 - C-69/14 - [Târşia] paras. 26 et seq.).
Paragraph 67
For the Federal Republic of Germany, the structure of the judiciary according to different jurisdictions, including different procedural rules, is important in this respect. Thus, for the assertion of claims against tax authorities for alleged violations of the General Data Protection Regulation, recourse to the tax courts is available under the provisions of the Fiscal Court Code (Federal Fiscal Court, decision of 28 June 2022 - II B 92/21 -, juris). For actions brought by the data subject against a controller due to a violation of data protection provisions within the scope of the General Data Protection Regulation when processing social data in connection with a matter pursuant to Section 51 Paragraphs 1 and 2 of the Social Court Act, legal recourse to the courts of social jurisdiction is available (Section 81b Paragraph 1 SGB X). Disputes concerning a right to information pursuant to Art. 15 GDPR within the framework of an employment relationship are decided by the labor courts (cf. Munich Labor Court, decision of August 2, 2023 – 3 Ta 142/23 –, juris), while those arising under general civil law are decided by the ordinary courts (for example: Federal Court of Justice, decision of February 21, 2023 – VI ZR 330/21 –, juris). A legal dispute concerning a right to information pursuant to Art. 15 GDPR between a public corporation and a member – as in this case – is a public law dispute of a non-constitutional nature, and there is no special assignment under federal law to another court within the meaning of Section 40 (1) of the Administrative Court Code (VwGO), which is why the administrative courts are available.
Paragraph 68
There are no objections to this differentiation, even if the access requirements to the court, the expected costs, and - in some cases - the requirements for the admissibility of actions differ to a greater or lesser extent under all procedural rules. With regard to equivalence and effectiveness (see above), all procedural rules of the Federal Republic of Germany satisfy the requirement of Article 79 (1) GDPR for an effective judicial remedy.
Paragraph 69
e) The territorial jurisdiction of the Stuttgart Administrative Court, which the plaintiff has brought before it, arises from Section 44 (1) Sentence 1 of the Federal Data Protection Act (BDSG) as a special provision to Section 52 of the Administrative Court Code (VwGO). The defendant is domiciled in Stuttgart. Whether the plaintiff would also have had the right, under Section 44 (1) Sentence 2 of the Federal Data Protection Act (BDSG), to bring an action before the territorially competent administrative court at the place of his habitual residence (VG Xxxx) or whether paragraph 2 of the provision specifically excludes this, does not need to be decided. Whether the defendant can be regarded as a public authority acting in the exercise of its sovereign powers appears rather doubtful.
Paragraph 70
f) The plaintiff correctly brought his direct action within the meaning of Article 79 (1) GDPR in the form of an action for an order pursuant to Section 42 (1), second alternative, of the Administrative Court Code (VwGO) – including the request for annulment of the defendant's two negative decisions – and not as a general action for performance. The permissible form of action for the judicial assertion of a claim for information against a public authority under Article 15 (1) GDPR is an action for an order (Federal Administrative Court, judgment of September 16, 2020 – 6 C 10/19 –, juris paragraph 12). This is because a decision on a data protection-related claim for information by a public authority constitutes an administrative act. The provision of information is preceded by an administrative decision, which must be made on the basis of a statutory review program (see, for example, Art. 15 (4) GDPR), and for which the authority must observe special procedural safeguards such as the obligation to provide reasons or to hold a hearing. Therefore, the provision of information by an authority on the basis of Art. 15 (1) GDPR is always preceded by an examination of possible grounds for exclusion and limitation.
Paragraph 71
Section 42 (2) Alternative 2 of the Code of Administrative Court Procedure (VwGO) applies in this respect. This means that the plaintiff must assert a violation of his or her own rights (and thus the possibility of a violation of subjective public rights). However, it is sufficient for this to be the case if the alleged violation appears possible. This can be assumed even if a violation of the plaintiff's own subjective rights cannot be clearly and unequivocally ruled out by any standard (cf. Federal Constitutional Court, decision of June 10, 2009, 1 BvR 198/08, juris, paras. 12 et seq.). According to this standard, there is a possibility that the plaintiff's own subjective public rights have been violated by the defendant's negative decision or refusal to provide the requested information. It appears possible that the plaintiff can derive a subjective right to further provision of information from the provisions of the General Data Protection Regulation, namely Article 15(1), second half of the sentence, so that the defendant's stated refusal fulfills the requirement of Section 42(2), second alternative, of the Code of Administrative Court Procedure (VwGO).
Paragraph 72
g) A similar situation applies with regard to the need for legal protection to be demanded for the administrative court action brought by the plaintiff. It is fundamentally compatible with the requirement to ensure effective legal protection to make the granting of legal protection dependent on an existing and ongoing need for legal protection. This requirement for a decision on the merits, common to all procedural rules, is derived from the principle of good faith (Section 242 of the German Civil Code), which also applies to procedural law, the prohibition of abuse of procedural rights, and the principle of the efficiency of state action, which also applies to courts (see, for example, Federal Constitutional Court, Second Senate, Third Chamber, Decision of March 4, 2008 – 2 BvR 2111/07 –, juris, paras. 25 et seq.). Such a requirement, prescribed by national procedural law, therefore does not conflict with the requirement under Article 79 (1) GDPR to provide an effective judicial remedy.
Paragraph 73
The procedural need for legal protection cannot, in any case, be denied here, since the defendant's refusal to provide (further) information constitutes an onerous administrative act against which the plaintiff is entitled to take action. The defendant's objection that the plaintiff has no legal need for (further) information because the defendant only processes data known to the plaintiff does not concern the admissibility of the action, but rather the merits of the action. If that were the case, a claim for information would (possibly) have to be denied.
Paragraph 74
h) Contrary to the defendant's objection, the plaintiff's most recent claim is also (just barely) sufficiently specific within the meaning of Section 253 (2) No. 2 of the Code of Civil Procedure, which is also applicable here via Section 173 of the Code of Administrative Court Procedure (VwGO). In particular, the Federal Labor Court has issued two decisions (judgment of April 27, 2021 – 2 AZR 342/20 – and judgment of December 16, 2021 – 2 AZR 235/21 –, both juris) comprehensively addressing the issue of filing an application in the event of a legal dispute concerning a right to information based on Article 15 (1), second half of the sentence, GDPR (in this case against the employer). The rapporteur fundamentally agrees with this.
Paragraph 75
A claim is sufficiently specific if it specifies the asserted claim by quantifying it or describing it in such a way that the scope of the court's decision-making authority (Section 308 (1) of the Code of Civil Procedure) is clearly defined, the content and extent of the substantive legal force of the requested decision (Section 322 (1) of the Code of Civil Procedure) are identifiable, the risk of the plaintiff's possible partial defeat is not shifted onto the defendant through avoidable imprecision, and any enforcement is not burdened by a continuation of the dispute in the enforcement proceedings (Federal Labor Court, judgment of December 16, 2021 – 2 AZR 235/21 –, loc. cit., para. 21, with further references). It is not sufficient to simply invoke statutory provisions that provide for the asserted claim; rather, the consequences resulting from these provisions must be considered in the individual case by the plaintiff when formulating their claim (see Federal Labor Court, judgment of April 25, 2001 – 5 AZR 395/99 – II. of the Reasons).
Paragraph 76
The Federal Labor Court emphasizes that, for reasons of effective legal protection, there must be a way to enforce the claim arising from Article 15 (1) sentence 2 GDPR procedurally. Procedural law is intended to implement substantive law, but not to unavoidably hinder its enforcement (see Federal Court of Justice, judgment of December 2, 2015 – IV ZR 28/15 – para. 10). It is particularly important to note that, through his request for information, a claimant only wants to obtain the information that will enable a more precise description of what personal data is stored about him (Federal Labor Court, judgment of December 16, 2021 – 2 AZR 235/21 –, loc. cit., marginal no. 26, with reference to Federal Court of Justice, judgment of December 2, 2015 – IV ZR 28/15 – marginal no. 9).
Paragraph 77
The use of terms requiring interpretation is considered if, on the one hand, further specification is not possible or reasonable for the plaintiff, and, on the other hand, the parties have no doubt as to their content, so that the scope of the application and the judgment is clear (Federal Labor Court, judgment of December 16, 2021 – 2 AZR 235/21 –, loc. cit., para. 22, with reference to Federal Court of Justice, judgment of December 2, 2015 – IV ZR 28/15 – para. 8). Consequently, in cases of doubt, claims must be interpreted in a manner consistent with the substance of the substantive claim pursued by the action (Federal Labor Court, judgment of December 16, 2021 – 2 AZR 235/21 –, loc. cit., para. 22, with reference to Federal Court of Justice, judgment of December 2, 2015 – IV ZR 28/15 – para. 10). However, a claim that merely repeats the text of the law is generally not suitable for settling a specific dispute between the parties with final and binding effect (Federal Labor Court, judgment of December 16, 2021 – 2 AZR 235/21 –, loc. cit., para. 22, with reference to Federal Court of Justice, judgment of December 21, 2011 – I ZR 190/10 –, para. 12).
Paragraph 78
For administrative court proceedings, the specific features applicable here must be considered in addition. Since the action for information must be brought as an action for an order (see above, letter f)), the claim usually seeks to obligate the party obliged to provide information, while annulling any conflicting decisions, to make a new decision on the fulfillment of the right to information pursuant to Article 15 (1), second half of the sentence, GDPR (and subsequently comply with the decision). However, within this framework, it is procedurally permissible – as here – to request that the party obliged to provide information be obligated to make a new decision, taking into account the court's legal opinion (see Section 113 (5) Sentence 2 of the Code of Administrative Court Procedure). In this situation, the specificity of the claim depends on the party requesting information presenting their claim in a manner that is comprehensible to the court, in order to enable the court to clearly formulate the presentation of the court's legal opinion required by Section 113 (5) Sentence 2 of the Code of Administrative Court Procedure (VwGO).
Paragraph 79
This has been done here. The rapporteur succeeded – albeit with difficulty – in identifying from the plaintiff's submissions those points to which the plaintiff's request for information specifically relates (see below under 2. lit. e) to u)).
Paragraph 80
i) Finally, there are no concerns about the admissibility of the claim in view of the fact that it could be established that the legal dispute would inevitably have to be repeated with the same content in the context of enforcement after its conclusion (see in this regard Federal Labor Court, judgment of December 16, 2021 – 2 AZR 235/21 –, loc. cit., para. 21, with further references). It should be noted that the defendant's willingness to provide information has not been particularly great in the past (see below under 2.). It may also be difficult to determine whether a right to information confirmed by the court in a judgment was ultimately fully satisfied. The plaintiff could always dispute that the defendant's statement that there is nothing more than what has now been submitted is not true and that further personal data must be available. Thus, impending enforcement proceedings would be almost identical to the current discovery proceedings. This would hardly change even if it were required that the plaintiff (then the enforcement creditor) not raise his doubts in this regard "out of the blue" (cf. Administrative Court of Bremen, judgment of April 22, 2022 - 4 K 1/21 -, juris, para. 33).
Paragraph 81
The rapporteur discussed with the parties in this regard during the oral hearing whether, in accordance with a so-called staged action pursuant to Section 254 of the Code of Civil Procedure, it would be procedurally necessary to require the plaintiff to supplement his request for information in the statement of claim by requiring the defendant to provide a sworn statement, through a responsible person, regarding the accuracy and completeness of the information provided. The defendant's representative rejected this and announced that, in the event of such a statement, he would unequivocally advise his management board to file an appeal. In any event, the plaintiff did not expand his statement of claim accordingly.
Paragraph 82
Even though civil court jurisprudence expressly considers such a procedure under Section 254 of the Code of Civil Procedure (ZPO) to be necessary in the context of judicial enforcement of a right to information under Article 15 (1) GDPR (Federal Labor Court judgment of December 16, 2021 - 2 AZR 235/21 -, loc. cit., para. 33, and judgment of April 27, 2021 - 2 AZR 342/20 -, loc. cit., para. 20, as well as, for example, Higher Regional Court of Koblenz, partial judgment of July 20, 2023 - 10 U 1633/22 -, juris, para. 41), the rapporteur has waived this requirement in the present case when examining the admissibility of the claim. The sole reason is the fact that in administrative proceedings, the defendant is usually a public authority – as is the case here. As such, the defendant is particularly bound by law and the rule of law – directly by Article 20 (3) of the Basic Law. The principle of mutual trust therefore requires the administrative courts to assume, until proven otherwise, that the defendant will comply with a judgment regarding its duty to provide information. In this situation, there is no need to order a prior affidavit – which is subject to penalty. Rather, the legislature has regulated in Section 172 of the Code of Administrative Court Procedure (VwGO) what must happen if an authority fails to fully comply with an obligation imposed on it in the judgment in cases under Section 113 (5) of the Code of Administrative Court Procedure (VwGO), namely, the threat and imposition of a coercive fine, if necessary repeatedly.
Paragraph 83
2. The action is thus admissible, but only to the extent established by the operative part. Only to the extent that the plaintiff is entitled to information pursuant to Article 15 (1), second half of the sentence, in conjunction with (3) GDPR, which the defendant has not yet fulfilled, was an obligation to be imposed. If the defendant's contested decision and its objection decision prove to be unlawful, they thereby violate the plaintiff's rights and are therefore subject to annulment (Section 113 (1) sentence 1 in conjunction with (5) VwGO). Otherwise, however, the action had to be dismissed.
Paragraph 84
a) The subject matter of the court's review is, as correctly assumed by the defendant, solely the plaintiff's application of January 12, 2021, as amended on January 21, 2021. From an overall assessment, it follows that the plaintiff's previous applications are to be considered as resolved under procedural law.
Paragraph 85
aa) This applies first of all to the plaintiff's original application of June 13, 2018. Since the parties failed to reach agreement on the scope of the obligation to provide information, the plaintiff initiated a complaint procedure with the Federal Commissioner for Data Protection pursuant to Art. 77 GDPR starting in August 2018. However, he no longer actively pursued his original application procedure. As the plaintiff's reaction to the defendant's final decision of June 1, 2021, shows, he considered this complaint procedure pursuant to Art. 77 GDPR to be decisive. The plaintiff expressly alleges that the decision of June 1, 2021, interferes with the complaint procedure.
Paragraph 86
Between August 27, 2018, and April 2, 2020, the plaintiff remained inactive regarding his application of June 13, 2018. He did not request a stay of the administrative proceedings, for example, until his appeal had been decided. The defendant was thus entitled to assume that the appeal proceedings pursuant to Art. 77 GDPR were now solely of interest to the plaintiff and that the request for information of June 13, 2018, had been resolved. The principle of good faith results in the forfeiture of a right to sue – under Section 75 of the Administrative Court Code – in the event of an authority's inaction (cf. Schenke in Kopp/Schenke, Administrative Court Code, 23rd ed., Section 75, para. 2) if the person concerned invokes the right late and has remained inactive under circumstances in which it would be reasonable to take action to uphold the law. This applies in particular if – as here – the person concerned has the right to file a new application at any time (Schenke, loc. cit., para. 3) and – as in the present case – also exercises this right.
Paragraph 87
bb) Likewise, the renewed request for information pursuant to Art. 15 GDPR, which was contained in the plaintiff's letter of May 16, 2020, to the defendant's management board/administrative board and which the defendant – consistently in this respect – included in the administrative file relating to the right to information as a "double transaction," is not a basis for judicial review. In response to this (second) request, the defendant provided the plaintiff with information on September 1, 2020, and sent a CD containing the data. The plaintiff also admits this. To the extent that he refers to a letter of his own dated September 3, 2020, which could be interpreted as an objection to the provision of information dated September 1, 2020, the plaintiff was unable to provide evidence that this objection was received by the defendant within the deadline. The letter dated September 3, 2020, is not contained in the defendant's administrative files at this time. Therefore, the proceedings regarding his second request for information have been definitively concluded.
Paragraph 88
cc) The plaintiff's renewed request for information dated January 12, 2021, which he further specified in a supplementary letter dated January 21, 2021, is therefore the request underlying the defendant's decision of June 1, 2021.
Paragraph 89
The plaintiff's request dated January 12/21, 2021 – and subsequently his claim – also includes – in addition to the mere provision of information – the provision of a copy of the data pursuant to Art. 15 (3) GDPR (see, however, the details provided below under letters e) to u)). Article 15 (3) GDPR does not regulate any additional independent claim against the data processor, but rather regulates the form of the provision of information (Franck in Gola/Heckmann, GDPR/BDSG, 3rd ed., Article 15 GDPR, paras. 35 and 36 with further references to the dispute).
Paragraph 90
b) The "formal" errors in the defendant's decision of June 1, 2021, alleged by the plaintiff, are either irrelevant or nonexistent.
Paragraph 91
aa) The fact that this "information decision" of June 1, 2021, pursuant to Art. 15 (1) GDPR, based on the application of January 12/21, 2021, was "out of time" with regard to the one-month deadline specified in Art. 12 (3) Sentence 1 GDPR, is irrelevant. The court can only grant an action for an injunction if the data subject has a claim. If they do not have one, this claim does not arise if the controller exceeds a standard deadline (for rejection) imposed on them.
Paragraph 92
bb) The plaintiff's argument that the decision of June 1, 2021, impermissibly interfered with the complaint procedure he was conducting with the Federal Commissioner for Data Protection is also flawed. The complaint procedure pursuant to Articles 77 and 78 GDPR exists independently of the assertion of the right to information under Article 15 (1) GDPR and a corresponding legal action under Article 79 (1) GDPR ("without prejudice"; see above under 1. b)).
Paragraph 93
cc) The "signature" of the decision of June 1, 2021, which the plaintiff repeatedly criticized, is also not objectionable. The plaintiff, of course, has no right to have a specific body of the defendant deal with his affairs personally. The defendant's external responsibility lies with the management board. This board acts through its responsible employees. The employee entrusted with data protection matters at the defendant signed the decision dated June 1, 2021. The fact that the plaintiff simultaneously initiated (or is still initiating) a complaint procedure with the Federal Commissioner for Data Protection pursuant to Articles 77 and 78 of the GDPR, and in doing so also "complained" about the work of the specific employee, does not render the employee biased within the meaning of the provisions of administrative procedure law (cf. Section 21 of the Administrative Procedure Act), nor is the employee legally prevented from participating (cf. Section 20 of the Administrative Procedure Act).
Paragraph 94
dd) This employee did in fact draft and sign both the initial decision dated June 1, 2021, and the subsequent objection decision dated July 8, 2021. However, contrary to the plaintiff's legal opinion, this is not detrimental. As a federal corporation under public law with self-governance (Section 1 (1) of the defendant's statutes), the defendant generally conducts pending objection proceedings itself (Section 70 of the Administrative Procedure Act in conjunction with Section 73 (1) Sentence 2 No. 3 of the Administrative Procedure Code (VwGO); see also Section 84 of the statutes). A general obligation to comply with the "four-eyes principle" is not contained in the provisions. Furthermore, the action for an order can only be granted if the plaintiff has a right to (further) information. If the plaintiff does not have this right, such a right would not arise even if the objection decision was possibly signed by an employee of the defendant who is not competent.
Paragraph 95
c) Contrary to the defendant's view, it cannot invoke a general right to refuse performance against the plaintiff's right to information under Article 15 (1) GDPR (cf. Franck in Gola/Heckmann, GS-DVO/BDSG, 3rd ed., GDPR Article 15, paragraph 50).
Paragraph 96
aa) There is no excessive request within the meaning of Article 12 (5), sentence 2, GDPR, which would justify the defendant refusing to act on the request.
Paragraph 97
aaa) A case of frequent repetition (“.. in particular ..”) within the meaning of this provision does not exist, since the application at issue here, dated January 12/21, 2021, is only the plaintiff's third application under Article 15 (1), second half of the sentence, GDPR since 2018 (see above, point 2, letter a)), and in this respect, at least the general assessment of Article 12 (3), second sentence, GDPR must be applied (Franck, loc. cit.), according to which one request per quarter is not objectionable.
Paragraph 98
bb) However, the plaintiff's application does not constitute an “excess” in the fact that the defendant's effort to provide information may be very extensive. The defendant stated to the Federal Commissioner for Data Protection that 3,000 documents, some of which are multi-page, were available. Compiling and printing the relevant documents would involve a disproportionate amount of work, taking into account that the plaintiff is already essentially familiar with the content of the administrative documents.
Paragraph 99
In principle, it is the responsibility of the processor of personal data to design its "IT architecture" in such a way that it can fulfill its obligations under the General Data Protection Regulation. The regulation entered into force in May 2016 and became generally binding in May 2018. If the defendant has failed to comply with extensive disclosure obligations under Article 15 (1), second half in conjunction with (3) GDPR over the past five and a half years, it must bear the resulting additional costs in each individual case.
Paragraph 100
In any case, case law has applied a (very) strict standard in this regard before a right to information can be classified as a breach of good faith – which, according to Article 8 (2) sentence 1 of the Charter of Fundamental Rights and in particular Article 5 (1) (a) of the GDPR, "hovers" over the entire processing operation (Franck, loc. cit., paragraph 51) (see already Regional Court of Kiel, judgment of April 4, 2008 - 8 O 50/07 - juris, paragraphs 25 et seq., on the previous Data Protection Directive in the case of a clinic that stored patient files in a stack of disorganized boxes in a hospital bunker = search reasonable). The rapporteur agrees with this in principle, and here as well.
Paragraph 101
ccc) An "excessive request" within the meaning of Article 12 (5) sentence 2 GDPR cannot be inferred from the fact that, from the defendant's perspective, the plaintiff is asserting his right to information under Article 15 (1) GDPR for reasons "unrelated to data protection" and that he lacks any legal interest in doing so. Irrespective of the question of whether this could even be interpreted as an excessive request, the European Court of Justice has ruled that there is neither an obligation for a person requesting information to state a motive for their request for information, nor does it preclude a request for information if the person concerned pursues purposes other than those mentioned in the first sentence of Recital 63 of the General Data Protection Regulation (ECJ, judgment of October 26, 2023 - C-307/22 -, juris, paragraphs 38 and 42).
Paragraph 102
bb) To the extent that the defendant invokes a right to refuse performance under Article 23 GDPR in conjunction with Section 34 (1) No. 2 (a) BDSG, it has not demonstrated the relevant requirements. They are also not obvious to the court. In principle, Article 23 (1) GDPR permits Member States – taking into account, among other things, the essence of fundamental rights – to restrict the rights under Articles 12 to 22 GDPR. Section 34 (1) No. 2 (a) BDSG permits a restriction of the right to information under Article 15 (1) GDPR in the event that data is stored solely because it may not be deleted due to statutory or statutory retention requirements, and providing the information would require disproportionate effort, and processing for other purposes is precluded by appropriate technical and organizational measures. The defendant does indeed invoke such a situation. However, it has not provided any information regarding the necessary element of "appropriate technical and organizational measures."
Paragraph 103
cc) The plaintiff's request for information is also not precluded by the so-called prohibition of chicanery (cf. Section 226 of the German Civil Code), a sub-case of the principle of good faith (Section 242 of the German Civil Code), which also applies in public law and is expressly referred to in Article 5 (1) (a) of the GDPR. It contains the prohibition of the abusive exercise of rights solely for the purpose of harming another person. It cannot be completely dismissed that the plaintiff's actions against the defendant also bear the characteristics of a "tit-for-tat" for years of "perceived injustice" in the processing of applications for assistance and benefits. However, this is not yet sufficient to deny the right to information under Article 15 (1), second half in conjunction with (3) GDPR. The plaintiff clearly also wants to gain an understanding of the lawfulness of the processing of his personal data. This is sufficient.
Paragraph 104
dd) Finally, it cannot be seen that the plaintiff's right to information under Article 15 (1), second half in conjunction with (3) GDPR has already been conclusively satisfied in this case, namely by the defendant's letters of July 2, 2018, and September 1, 2020, including the CD submitted at that time, as well as by the documents submitted after the conclusion of the oral hearing on the basis of the defendant's right to submit written submissions granted by the court (see below).
Paragraph 105
d) The plaintiff's claim for "complete information" has no independent, operative meaning, regardless of the category of personal data. However, the interpretation of the plaintiff's applications and letters in the administrative proceedings and in the trial, his argument that he himself cannot determine the missing data and needs "a clear picture of the entire process," as well as the reference to the case law of the Federal Court of Justice (judgment of June 15, 2021 - VI ZR 576/19 -, juris) demonstrate that, from the plaintiff's perspective, the plaintiff's request for information - including his request under Art. 15 (3) GDPR for information by providing copies of the data - is aimed at the entire content of all existing documents in the individual categories (see below for more details under points e) to u)). In detail:
Paragraph 106
e) To the extent that the plaintiff requests information about "emails - external/internal" that are related to him personally (according to his own statements, he himself has never communicated with the defendant by email), the following applies:
Paragraph 107
aa) In principle, the term "personal data" within the meaning of the General Data Protection Regulation is to be understood broadly (ECJ, judgment of May 4, 2023 - C-487/21 -, juris, paragraph 23, with reference to the case law already issued on the Data Protection Directive <Directive 95/46>, ECJ, judgment of December 20, 2017 - C-434/16 -, juris, paragraph 34). The use of the term "any information" in connection with the definition of "personal data" in Article 4(1) GDPR reflects the EU legislature's intention to give this term a broad meaning, potentially encompassing all types of information, both objective and subjective, in the form of opinions or assessments, provided that it is information "about" the person in question (ECJ, C-487/21, loc. cit., paragraph 23). E-mail messages that are stored or otherwise processed within the meaning of Article 4(2) GDPR may thus also be subject to a right to information under Article 15 GDPR, provided they contain personal data. For example, in Case C-487/21 (ECJ, loc. cit., paragraphs 10 and 12), the referring court had expressly referred to emails, without the European Court of Justice having expressly excluded them in its decision on the scope of the right to information.
Paragraph 108
However, in the rapporteur's opinion, a further distinction must be made here in several respects. If the issue concerns email messages stored on an employee's work account – for example, in the "Sent Messages" or "Received Messages" folder because the employee has exchanged information about the plaintiff with another employee – the defendant is not "responsible" for the storage, i.e., for the processing, of this data, so that an obligation to provide information is excluded in this respect. Such "private" data processing without an order from the defendant constitutes "excessive processing" by the employee in question. Furthermore, the defendant would not be prevented from requesting its employees to delete such email messages, if any, from the work computers.
Paragraph 109
E-mail messages that are stored as part of a specific process, for example, during the processing of benefits or regarding other input from the plaintiff, and that are stored as such, are subject to disclosure if they contain personal data as described above. However, this must involve more than abstract processing instructions or similar statements ("Please process carefully"; "Please send a copy to the audit department after completion"; "Please consider previous process "X"). This is because such information is not information of an objective or subjective nature about the plaintiff. Only if such a message contains additional information about the plaintiff ("The member has already filed six objections in the last year"; "The alleged course of treatment appears implausible"), i.e., an assessment of the plaintiff, does it constitute personal data that is subject to disclosure.
Paragraph 110
Finally, legal analyses stored in the form of an email, for example, regarding a benefit process, are subject to disclosure only with regard to any personal data that may be contained in the message. Only the data itself, which may be included in the legal analysis, constitutes "personal data" within the meaning of Article 15 (1), second half of the GDPR. However, this classification does not apply to the analysis itself (expressly, see ECJ, judgment of July 17, 2014 – C-141/12 and C-372/12 –, juris paragraph 48, regarding the identical provision in the preceding Data Protection Directive <Directive 95/46>; that this case law remains relevant, see ECJ, judgment of May 4, 2023 – C-487/21 –, juris, paragraph 23). A summarized legal analysis, for example, regarding a service transaction, i.e., how the defendant's employee assesses the existence of a claim, is not personal data about the plaintiff.
Paragraph 111
bb) Finally, the above principles also apply identically to external email communications, if any exist and are stored and thus processed by the defendant, i.e., with experts, treating physicians, or other service providers.
Paragraph 112
cc) The differentiation made here cannot be circumvented in the plaintiff's interest by the plaintiff insisting that he is entitled to "copies" under Art. 15 (3) GDPR and that he is seeking "complete information." As the European Court of Justice emphasizes (judgment of October 26, 2023 - C-307/22 - loc. cit., para. 72), this provision only grants a right to a (comprehensible) copy of the data, but not to a copy of the documents. The obvious motive behind the plaintiff's request, to obtain "full access to the files" of all the defendant's processes and documents concerning him under Article 15 of the GDPR, is completely unenforceable. In its decision of July 17, 2014, concerning Directive 95/46/EC (C-141/12 and C-372/12, loc. cit., para. 46), the European Court of Justice already clarified the distinction between personal data and documents containing, among other things, personal data (also Finance Court of Munich, judgment of May 5, 2022 – 15 K 193/20 –, juris, para. 55). The General Data Protection Regulation does not provide a right to the disclosure of the latter.
Paragraph 113
The defendant has the choice of whether to extract the data subject to disclosure from the relevant documents (e-mail messages) and merely provide the storage location ("E-mail message dated XX.XX.XXXX to Department XX: Notification of receipt of an objection from the plaintiff dated XX.XX.XXXX regarding the benefit notice dated XX.XX.XXXX"), or whether to make copies of the entire document and thereby obscure the contents not subject to disclosure (ECJ, judgment of July 17, 2014 – C-141/12 and C-372/12, loc. cit., paragraph 58) and then make them available to the plaintiff, whereby the rights of third parties must be protected in this obscuration (cf. ECJ, judgment of May 4, 2023 – C-487/21 –, juris, Paragraph 45).
Paragraph 114
Only if data absolutely requires contextualization for its understanding may – in exceptional cases – the provision of entire documents be required (ECJ, judgment of October 26, 2023 – C-307/22 –, juris, paragraph 74 with further references). This is rather unlikely in the case of personal data contained in email messages.
Paragraph 115
The defendant may, at its discretion, provide the information it is thus obliged to provide by means of paper copies (taking into account any necessary "redactions") or in electronic form, since the plaintiff himself always communicates (including with the court) in writing. The faxing practiced by him, even if it is done from a PC, is not electronic communication within the meaning of Article 15 (3) sentence 3 GDPR. If the defendant provides the plaintiff with data in electronic form, it acts properly if it uses a "common format" (as defined in Art. 15 (3) Sentence 3 GDPR). If the plaintiff does not have appropriate software to read "common formats," he must seek redress. His objection to the CDs already sent to him by the defendant, claiming they contained "encrypted data," certainly points in this direction, as does the fact that the numerous spelling errors in the plaintiff's letters (most recently, in many cases, "dediziert" instead of "dezidiert") seem to demonstrate that the word processing program used by the plaintiff lacks a spelling check function and that the plaintiff's IT equipment may be deficient.
Paragraph 116
f) The above also applies in its entirety to the extent that the plaintiff requests access to other documents relating to submissions made by him to the defendant, namely "submission of my letters" and "signatures," "hearing of the management board," "letters," "notes," "processing and forwarding notes," and "replies, etc." regarding "complaints from the management board's complaint log" that he submitted. To the extent - which is also likely to be the exception - the plaintiff's personal data was disclosed for further processing by the responsible body, the data still stored is subject to disclosure in the sense described above, but nothing more.
Paragraph 117
g) A similar provision applies to the extent that the plaintiff requests information regarding statements made to and correspondence with the Federal Office for Posts and Telecommunications (BAPT) by the defendant concerning him personally.
Paragraph 118
aa) In this respect, the defendant cannot instruct the plaintiff that the plaintiff must contact BAPT itself, as BAPT has reserved the right to answer inquiries under the General Data Protection Regulation. This applies – of course – only with regard to the plaintiff's personal data that BAPT processes within the meaning of the General Data Protection Regulation, i.e., in particular, stores. However, to the extent that such data is stored on the defendant's premises – including, for example, in the context of correspondence – the defendant is a processor and is therefore obligated to provide information under Art. 15 GDPR.
Paragraph 119
bb) However, the principles outlined above are fully applicable in this regard as well (see 2. e) aa) and cc above). In any case, the court has not been provided with evidence that the defendant has already fully fulfilled this right to information (as regards the relevant date in this regard, see lit. u) below).
Paragraph 120
h) The above also applies to the extent that the defendant has stored documents relating to "court proceedings, etc." conducted with the plaintiff. If these documents contain personal data as described above, they are subject to a duty to provide information. Legal analyses by the defendant that preceded, for example, a letter to the court or similar internally are not (see above, for details, 2. e)).
Paragraph 121
i) To the extent that the plaintiff requests information about personal data from "documents relating to assistance" pursuant to Art. 15 GDPR, such a right to information only exists in part. The so-called "joined procedure" practiced by the defendant is known to the court. The rapporteur has been handling claims for benefits and assistance against the defendant for years (the latter only if the plaintiff has their official residence in the court district). In this case, only a single decision is issued that determines assistance benefits and statutory insurance benefits. The defendant does not maintain its own state aid procedural files to which a right to information under Art. 15 GDPR could directly relate.
Paragraph 122
Whether these combined proceedings are free of legal concerns in all cases does not need to be decided in this case, since only the plaintiff's right to information is the subject of the proceedings. The special obligation to delete data under state aid law provided for in Section 113 (2) sentences 1 to 3 of the Federal Act on the Protection of Personal Data (BBG) could possibly be circumvented by the "combined proceedings" by arguing that documents are stored (only) for the purpose of insurance benefits.
Paragraph 123
In any event, the plaintiff has a right to information under Article 15 (1), second half in conjunction with Article 15 (3) GDPR regarding which documents relating to treatment processes containing personal data (namely, submitted invoices, diagnoses, expert opinions, etc.) are stored by the defendant. As the European Court of Justice has ruled (judgment of January 12, 2023 – C-154/21 –, juris, paragraph 38), the right to information is inextricably linked, among other things, to the data subject's right to erasure under Article 17 GDPR. Irrespective of the fact that, due to the combined procedure practiced by the defendant, all of the personal data processed in this way are not "pure" aid documents, they are in any case also aid documents. Since a right to erasure under Article 17 (1) (e) GDPR in conjunction with the national provision of Section 113 (2) sentences 1 to 3 of the Federal Employment Agency Act (BBG) is at least conceivable in this respect, a right to information under Article 15 GDPR is unavoidable.
Paragraph 124
To the extent that the defendant stores or otherwise processes the plaintiff's personal data within the meaning of the General Data Protection Regulation in order to decide on the conditions and amount of aid claims, a right to information also exists. In this respect, however, reference is made to the following explanations (under letter o)) regarding "financial data."
Paragraph 125
j) The plaintiff does not have a right to information under Article 15 (1) second half in conjunction with Article 15 (3) GDPR with regard to the defendant's benefit system known as "direct billing." The defendant denies that there were any direct billings from service providers with regard to the plaintiff. Without the plaintiff at least approximately specifying which services might be involved in this regard, such as information on hospital stays for which the plaintiff himself was never billed, or corresponding physiotherapy, psychotherapy, orthopedic services, or other medical aids, the request for information appears to be a "blank slate" claim (cf. Administrative Court of Bremen, judgment of April 22, 2022 – 4 K 1/21 –, juris, para. 33).
Paragraph 126
k) To the extent that the plaintiff requests information regarding the defendant's personal data relating to his private long-term care insurance, there is a right to information pursuant to Art. 15 (1) Sentence 1, Second Half Sentence (c) GDPR. This provision not only requires the identification of the recipient of personal data – in this case, specifically, the "Community of Private Insurance Undertakings for the Implementation of Long-Term Care Insurance pursuant to the Nursing Care Act of May 26, 1994, for Members of the Postal Officials' Health Insurance Fund and the Health Insurance Fund for Federal Railway Officials (GPV)" – but, through the wording "the personal data" (underlined by the rapporteur), also requires disclosure of the total data transmitted to this recipient. Therefore, these data are all subject to a duty to provide information.
Paragraph 127
To the extent that the defendant has also maintained email correspondence with the GPV regarding the plaintiff, the above statement under point e) applies.
Paragraph 128
However, the plaintiff's general statement that the defendant must have stored data relating to his private long-term care insurance, beyond the amount of contributions collected by the defendant for the GPV, does not give rise to a right to information. In this respect, it remains completely unclear which data the plaintiff suspects in this regard. This is again a "blank" argument (see above under point j)).
Paragraph 129
l) However, there is no right to information under Article 15 (1), second half in conjunction with (3) GDPR with regard to the so-called "submission app" used by the defendant.
Paragraph 130
With regard to the identity of the third party who gains access to the plaintiff's personal data, the defendant has already fulfilled its right to information. During the introduction of this application, it stated in general terms, i.e., also to the plaintiff, that the app is operated by IBM Germany. To the extent that this operator stores the device with which the plaintiff communicates, this operator is the processor and thus the controller, not the defendant.
Paragraph 131
m) To the extent that the plaintiff stated at the oral hearing that he had learned that his benefit applications were always processed at a "special workstation" due to an internal directive of the defendant, which the defendant did not dispute, the linking of the plaintiff's personnel data with an established "special workstation" constitutes personal data subject to disclosure within the meaning described above pursuant to Article 15 (1), second half in conjunction with (3) GDPR. If, for example, this involves generally refraining from automated application processing in the plaintiff's case, in deviation from Section 77a of the defendant's statutes, for example due to the frequency of objection procedures or similar, such a stored assessment of the plaintiff would be subject to disclosure.
Paragraph 132
n) The data stored by the defendant on marital status, including those of dependents eligible for consideration under state aid law and the statutes, are also subject to disclosure under Article 15 (1) 2nd half in conjunction with Article 15 (3) GDPR. Since, according to the case law of the European Court of Justice, the right to information under Article 15 GDPR is intended to serve the exercise of further rights under the General Data Protection Regulation (cf. judgment of January 12, 2023 – C-154/21 –, juris, loc. cit.), and corrections appear conceivable at any time with regard to family connections and dependents, this is obvious.
Paragraph 133
o) A similar situation applies to all "financial data" stored by the defendant, including "tax data," as personal data of the plaintiff. This also includes all stored conclusions and references to this data relating to the plaintiff, including, for example, with regard to relatives (cf. Section 6 (2) in conjunction with Section 4 (1) BBhV), as well as the amount of co-payments, cost shares, and deductibles, etc., to the extent that they are stored.
Paragraph 134
p) Corresponding data, i.e., data subject to disclosure under Article 15 (1), second half of the sentence, in conjunction with (3) GDPR, are all personal data relating to the plaintiff's contribution amount. This also includes data on surcharges, suspension contributions, the existence of any supplementary insurance, data on the due date of contributions, and, if applicable, provisions linked to the plaintiff.
Paragraph 135
q) All stored personal data relating to future benefit grants or restrictions are also subject to disclosure requirements pursuant to Article 15 (1), second half of the sentence, in conjunction with Article 15 (3) GDPR. This applies both to coverage commitments for future benefits, to cases where benefits are only reimbursed in the event of a repeat incident if time intervals are observed (cancer screening, visual aids, etc.) – whereby the calendar date of the previous incident is also relevant – and also if data is stored to comply with maximum limits for the consideration of expenses (two-implant rule, Section 15 (2) BBhV, etc.). In this respect, the requirement of comprehensibility pursuant to Art. 15 (3) GDPR is of central importance (cf. ECJ, judgment of October 26, 2023 – C-307/22 –, juris, guiding principle 3). This means that in order to be able to assert claims for rectification, the data subject must be informed about stored data in context, making the respective consequences clear to him or her.
Paragraph 136
r) Stored documents relating to the plaintiff's health status – including the date they were created –, X-rays, blood tests, etc., are also personal data subject to disclosure if they are stored by the defendant. The dental chart most recently submitted by the defendant was therefore rightly included in the disclosure. However, the requirement of comprehensibility under Article 15(3) GDPR is specifically lacking here (cf. ECJ, judgment of October 26, 2023 – C-307/22 –, loc. cit.). The reproduction submitted to the court is almost illegible, and the right to information is therefore not yet fulfilled in this respect.
Paragraph 137
s) A similar situation applies to the extent that the defendant has now submitted tables of diagnoses made to the plaintiff, which it has stored. The current reproduction of these tables makes no sense, since the approximately 210 columns with dates could not really be assigned to the disproportionately larger number of columns with diagnoses (some with, some without ICD codes).
Paragraph 138
t) Finally, the plaintiff has no right to information under Article 15 GDPR with regard to deleted data. Although Article 4 (2) GDPR also includes the deletion of data in the definition of "processing," completely deleted data cannot, logically speaking, be the starting point for the right to information under Article 15 (1), second half in conjunction with Article 15 (3) GDPR. What no longer exists cannot be disclosed. However, if a deletion process is still documented and stored, at least in terms of its scope, this constitutes a (single) piece of personal data relating to the data subject, which would be subject to disclosure ("Deletion process on XX.XX.XXXX: all documents submitted by the plaintiff from the calendar year XXXX and before").
Paragraph 139
u) Finally, the temporal limitation that the plaintiff added to his procedural request for an obligation to provide information ("for the period 10 years back from the date of final judgment"), and which he also asserted against the defendant in his pre-trial letters ("data from the last 10 years (the storage period)"), cannot lead to a corresponding tenor. The action had to be dismissed in this respect as well. According to Art. 15 (1) GDPR, the personal data processed by the controller is the data subject to the obligation to provide information. The right to information therefore always has a present-day relevance - also according to the wording of the provision ("...data are processed;"; regarding the stored deletion process as the current date, see above t)).
Paragraph 140
3. The decision on costs follows from Section 155 (1) Sentence 1, Second Alternative, of the Code of Administrative Court Procedure (VwGO). The court assesses the plaintiff's failure to a degree of two-thirds in light of his very broadly formulated request (see above, point 2, letters e) to u)).
Paragraph 141
The appeal was admissible pursuant to Section 124a, Paragraph 1, Sentence 1 in conjunction with Section 124, Paragraph 2, No. 3 of the Code of Administrative Court Procedure (VwGO). The appeal proceedings offer the opportunity to clarify questions of fundamental importance regarding the admissibility of data protection-related information claims (requirement for the specificity of the claim; necessity of a staged action within the meaning of Section 254 of the Code of Civil Procedure), as well as regarding the scope of the right to information and the provision of a copy of the data.
Paragraph 142
Decision of November 30, 2023
Paragraph 143
The value in dispute is set at
Paragraph 144
€10,000
Paragraph 145
pursuant to Section 63 (2) Sentence 1 in conjunction with Section 52 (1) of the German Act on the Protection of Personal Data (GKG).
Paragraph 146
The court does not apply the catch-all provision of Section 52 (2) of the German Act on the Protection of Personal Data (GKG). While the information requested by the plaintiff from the defendant has no economic value for him in the true sense of the word, what he is seeking, in principle, is an economically measurable service from the defendant, namely that the defendant's employees address his claim and, using their labor (for which remuneration) to be paid, search through approximately 3,000 documents, some of which are multi-page, for data requiring disclosure, in accordance with the court's legal opinion. The court estimates the personnel requirements and the associated costs at a minimum of €10,000.




